{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "15.0.0"
              },
              {
                "last_affected": "23.6.6"
              },
              {
                "introduced": "24.0.0"
              },
              {
                "last_affected": "24.9.8"
              },
              {
                "last_affected": "24.9.9"
              },
              {
                "introduced": "25.0.0"
              },
              {
                "last_affected": "25.0.2"
              },
              {
                "last_affected": "25.0.3"
              },
              {
                "introduced": "2.2.0"
              },
              {
                "last_affected": "2.13.0"
              },
              {
                "introduced": "3.0.0"
              },
              {
                "last_affected": "23.6.7"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "f629e550348397e0b4a976afbbf2594c8d21332d"
            },
            {
              "introduced": "f5bd08834302a4f461b920dea6d0be8808e88a50"
            },
            {
              "last_affected": "c376b4e8a9991df767172e3fef4dabe059178a68"
            },
            {
              "last_affected": "a7e103f0bca6bca9eefa1039916ef1c1a8156b0a"
            },
            {
              "introduced": "d3e5f6448dd0563cd62137836ea4fd5be69c9067"
            },
            {
              "last_affected": "d50248fd4f0d9b50b784db977f72c22edc22e82e"
            },
            {
              "last_affected": "9eec2f7d65b74e8593882fce0f134c2503b6a7d6"
            },
            {
              "introduced": "8fd9c0846224fabc22b37124952555f6bf920518"
            },
            {
              "last_affected": "02bb22cdab8d90dcfdce70dc05842481d0ed17be"
            },
            {
              "introduced": "4b6ca4330163c4e976b32d03880fe2154a9d1ca7"
            },
            {
              "last_affected": "90076b751b26030a271942c3d523b732ced97219"
            }
          ],
          "repo": "https://github.com/vaadin/flow",
          "type": "GIT"
        },
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "14.2.0"
              },
              {
                "fixed": "14.14.1"
              },
              {
                "introduced": "15.0.0"
              },
              {
                "fixed": "23.6.7"
              },
              {
                "introduced": "24.0.0"
              },
              {
                "fixed": "24.9.10"
              },
              {
                "introduced": "25.0.0"
              },
              {
                "fixed": "25.0.4"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "8d628e5e572caafefd44db574106bd3a10ac48cd"
            },
            {
              "fixed": "ecdbd581aa8f05d30390b791c53a3d61a25fda3c"
            },
            {
              "introduced": "354ad0186b5e61b548adad84de03af297dc6f2a6"
            },
            {
              "fixed": "e576f406b9f7f28cc7df549145e7983cd4efb25c"
            },
            {
              "introduced": "6aea8fa5fdf6b2c7645a54e1bc38978ee40b26df"
            },
            {
              "fixed": "9a278f5fe6b4511aca3f293709c94a9960d1011c"
            },
            {
              "introduced": "f7582b4be60fe9100489237bb8b022783a288766"
            },
            {
              "fixed": "209e5351251276053f1bd071684ff43caaeda378"
            }
          ],
          "repo": "https://github.com/vaadin/platform",
          "type": "GIT"
        },
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:vaadin:vaadin:*:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "14.2.0"
              },
              {
                "fixed": "14.14.1"
              },
              {
                "introduced": "15.0.0"
              },
              {
                "fixed": "23.6.7"
              },
              {
                "introduced": "24.0.0"
              },
              {
                "fixed": "24.9.10"
              },
              {
                "introduced": "25.0.0"
              },
              {
                "fixed": "25.0.4"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "87a4778118121215b10f01979996b1ab99cab62a"
            },
            {
              "fixed": "2fb28ea68d4354625468e8d53dd87e892e466057"
            },
            {
              "introduced": "9efda1b1e0a27769eef9292dd7799d8fea77e633"
            },
            {
              "fixed": "220a7e475d06b7442c8f6f45ce4b08c78f19e828"
            },
            {
              "introduced": "a45cc881358732b3d594b20750f1369a65d7237a"
            },
            {
              "fixed": "18118749102f8743c54f2f6f63bc0d66aac6f9a9"
            },
            {
              "introduced": "1bbe0e9e6b57f11d3fbb7b58810f72fbf106ef43"
            },
            {
              "fixed": "e38a47025e60dc6f30dd1cdceddcf943e1cf5ab8"
            }
          ],
          "repo": "https://github.com/vaadin/vaadin",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Vaadin",
    "cwe_ids": [
      "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2741.json"
  },
  "details": "Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Vaadin 14.2.0 through 14.14.0, 15.0.0 through 23.6.6, 24.0.0 through 24.9.8, and 25.0.0 through 25.0.2. \n\nVaadin’s build process can automatically download and extract Node.js if it is not installed locally. If an attacker can intercept or control this download via DNS hijacking, a MITM attack, a compromised mirror, or a supply chain attack, they can serve a malicious archive containing path traversal sequences that write files outside the intended extraction directory.\n\n\nUsers of affected versions should use a globally preinstalled Node.js version compatible with their Vaadin version, or upgrade as follows: 14.2.0-14.14.0 to 14.14.1, 15.0.0-23.6.6 to 23.6.7, 24.0.0-24.9.8 to 24.9.9, and 25.0.0-25.0.2 to 25.0.3 or newer.\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24, 25 version.",
  "id": "CVE-2026-2741",
  "modified": "2026-08-07T11:31:11.334339784Z",
  "published": "2026-03-10T12:08:30.515Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://repo.maven.apache.org/maven2"
    },
    {
      "type": "WEB",
      "url": "https://vaadin.com/security/cve-2026-2741"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2741.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2741"
    },
    {
      "type": "FIX",
      "url": "https://github.com/vaadin/flow/pull/23125"
    },
    {
      "type": "FIX",
      "url": "https://github.com/vaadin/flow/pull/23130"
    },
    {
      "type": "FIX",
      "url": "https://github.com/vaadin/flow/pull/23131"
    },
    {
      "type": "FIX",
      "url": "https://github.com/vaadin/flow/pull/23133"
    },
    {
      "type": "FIX",
      "url": "https://github.com/vaadin/flow/pull/23135"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/vaadin/flow"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/vaadin/platform"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:D/RE:L/U:Amber",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Zip Slip Path Traversal on Node Unpack"
}